Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Samovolná platba přes Paypal

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
karelsvoboda
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 12 lis 2015 14:55

Samovolná platba přes Paypal

#1 Příspěvek od karelsvoboda »

Zdravím,
mám tu pro mne takovou záhadu, se kterou si nevím rady, jak a jestli je vůbec možná, nebo jestli se jedná jen o náhodou:

Mám v přízemí kancelář, s pár počítači a sítí, a o dvě patra výše byt, sítě nejsou nijak propojeny, pouze mám internet od stejného poskytovatele. (v poslední době jsem nepřenášel ani žádné flash paměti, vyjma zrcadlovky) Včera k večeru jsem si v kanceláři objednal pár věcí, (ne z ebaye) zaplatil přes Paypal, přišli mi dva emaily, kterým jsem nevěnoval pozornost. Po chvíli jsem se odebral nahoru do bytu, a všiml si, že je počítač odhlášený, i když jsem věděl, že jsem ho nachával zaplý. Po přihlášení mi vyskočila hláška "systém windows se za minutu vypne". S tím jsem si poradil instalací bitdefenderu (přiznám se, že do té doby jsem na počítači antivir neměl), jednalo se o .bat soubor v "po spuštění" a nějaký ssscheduler.exe. Bylo tam ještě několik zpětně divnějších věcí, jako odhlášení z FB a podobné, ale tomu jsem nevěnoval pozornost, s tím, že to dořeším ráno a šel spát.

Ráno jsem to neřešil a šel do kanceláře, kde jsem našel můj (druhý) počítač odhlášený (i když jsem si opět byl jistý, že jsem ho zase ze zlozvyku nechal zaplý), nicméně žádné zvláštnosti podobné stavu počítače nahoře jsem nezaznamenal. Do chvíle kdy jsem otevřel mail a zjistil, že mi z Paypalu včera přišlo potvrzení na nákup iPhonu z ebaye (do Alžírska), deset minut před mým vědomým nákupem (mimo ebay). Počítač dole má antivir, žádné příznaky, nic podivného. Heslo k Paypalu nemám ani na jednom počítači uložené. Další podivná věc je, že mi teprve včera přišla výplata (před tím jsem na účtě měl minimum peněz), na stav účtu jsem se před objednávkou díval přes internetové bankovnictví. Snažím se nebýt paranoidní, protože v kanceláři je další počítač, přes který se chodí do internetového bankovnictví firmy, což by byl větší průser, než objednávka iPhonu :) Tak jestli je možné, že se vir šíří po síti, doporučení ohledně postupu u dalších pc?

Předem děkuji za pomoc :)

log z rsitu počítače v kanceláři:

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Franta at 2015-11-12 14:59:12
Microsoft Windows 7 Professional  Service Pack 1
System drive C: has 27 GB (9%) free of 288 GB
Total RAM: 8106 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:59:17, on 12.11.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18098)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe
C:\Program Files\trend micro\Franta.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O2 - BHO: IEPlugin - {C63CD127-A1CB-4D49-A4F7-D6F88A917BE6} - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKCU\..\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {B8FB8104-FDC9-4339-8AFF-2EE4C8C92998} (AMCCtrl Class) - http://192.168.0.109/AVC_AX_NVR.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 12 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.12.0) - ABBYY Production LLC - C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apache - Apache Software Foundation - C:\PROGRA~2\EASYPH~1.1VC\binaries\apache\bin\eds-httpd.exe
O23 - Service: Autodesk Content Service - Autodesk, Inc. - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: DisplayFusionService - Binary Fortress Software - C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Bitdefender Antivirus Free Edition (gzserv) - Bitdefender - C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe
O23 - Service: HyperW7 Service (HyperW7Svc) - Lenovo Group Limited - C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\Windows\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Identity Protection Technology Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Power Manager DBC Service - Lenovo - C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIPAppService - Symantec Corporation - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-20001 (WMSVC) - Unknown owner - C:\Windows\system32\inetsrv\wmsvc.exe (file missing)
O23 - Service: Wacom Consumer Service (WTabletServiceCon) - Wacom Technology, Corp. - C:\Program Files\Tablet\Pen\WTabletServiceCon.exe

--
End of file - 14734 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
"C:\Program Files\Tablet\Pen\WTabletServiceCon.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 24982816
\??\C:\Windows\system32\conhost.exe "642617848-1638791986-62874050-682716161-1299930238-1427781644474467201329596074
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe" -service
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\PROGRA~2\EASYPH~1.1VC\binaries\apache\bin\eds-httpd.exe" -k runservice
C:\Windows\system32\svchost.exe -k apphost
C:\PROGRA~2\EASYPH~1.1VC\binaries\apache\bin\eds-httpd.exe -d "C:/Program Files (x86)/EasyPHP-DevServer-14.1VC11/binaries/apache"
"C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\Windows\system32\CxAudMsg64.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service
"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe"
C:\Windows\system32\svchost.exe -k iissvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
WLIDSvcM.exe 3252
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\alg.exe
"C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"taskhost.exe"
"C:\Program Files\Tablet\Pen\Pen_TabletUser.exe" 
"C:\Program Files\Tablet\Pen\WacomHost.exe" "C:\Program Files\Tablet\Pen\Pen_Tablet.exe" au
"C:\Program Files\Tablet\Pen\Pen_Tablet.exe" au
"C:\Program Files\Tablet\Pen\Pen_TouchUser.exe" 
"C:\Windows\system32\Dwm.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
"C:\Windows\System32\hkcmd.exe" 
"C:\Windows\System32\igfxpers.exe" 
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe" 
"C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe" 
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Secunia\PSI\psi_tray.exe" 
"C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe" "C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe" 
"C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" 
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" 
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe" 
"C:\Windows\System32\rundll32.exe" C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
"C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\GWX\GWX.exe" 
"C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe" "3716" "131792" "262300" "66328" "65712" "65766" "f912b9c5-2da6-4b11-bdab-bb7fff5906be" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookWIN6032_38594AEE-CC65-4649-A724-CB6213FFB2A4.dll" "Software\Binary Fortress Software\DisplayFusion" "Software\Binary Fortress Software\DisplayFusion\Session" "0" "61"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6064.exe" "3716" "131792" "262300" "66328" "65712" "65766" "f912b9c5-2da6-4b11-bdab-bb7fff5906be" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookWIN6064_86A5603D-5C6B-493F-AE9C-09122EBA58B2.dll" "Software\Binary Fortress Software\DisplayFusion" "Software\Binary Fortress Software\DisplayFusion\Session" "1" "61"
"C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe" /service
"taskhost.exe"
C:\Windows\explorer.exe 
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" 
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe" 
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="28156.0.1109762787\1076228409" "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" E7CF176E110C211B 28156 "\\.\pipe\gecko-crash-server-pipe.28156" plugin
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe" --proxy-stub-channel=Flash29072.6697A108.28250 --host-broker-channel=Flash29072.6697A108.14596 --host-pid=29072 --host-npapi-version=28 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll"
"C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_232.exe" --channel=29108.001BF40C.1112780165 --proxy-stub-channel=Flash29072.6697A108.28250 --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll" --host-npapi-version=28 --type=renderer

"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-28059927-b1d6-45b6-9611-6d7bc8374fad -SystemEventPortName:HostProcess-4f35a815-7ec6-431e-8d30-1af95a38bb17 -IoCancelEventPortName:HostProcess-73656453-760e-491e-ba70-7b2ad3f626a0 -NonStateChangingEventPortName:HostProcess-1860ee7c-e71f-4f46-b7eb-a018cfb32140 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:623d778d-6a00-4da3-84d7-6d4393ce1130 -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-008491d5-d006-4fd0-978d-9baa6dab82dd -SystemEventPortName:HostProcess-35ab46a9-5d61-4011-8c92-e9407f3e81a7 -IoCancelEventPortName:HostProcess-f3e5f2fd-1910-4d22-a876-11208e5dc2cb -NonStateChangingEventPortName:HostProcess-c5981887-df68-42a8-a373-aa8dc506c5b5 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:7a7b4f43-2faf-4866-9bfd-b7bcd0c45b8d -DeviceGroupId:
"C:\Users\Kryštof\Downloads\RSITx64.exe" 
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

=========Mozilla firefox=========

ProfilePath - C:\Users\Kryštof\AppData\Roaming\Mozilla\Firefox\Profiles\supv2zeo.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@research.microsoft.com/HDView]
"Description"=Microsoft Research HD View
"Path"=C:\Program Files (x86)\Microsoft Research\HD View\nphdview.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\wacom.com/WacomTabletPlugin]
"Description"=
"Path"=C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 18.0.0.232 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_232.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=C:\Windows\system32\Wat\npWatWeb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@wacom.com/wtPlugin,version=2.1.0.7]
"Description"=WebTablet Plugin API
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64]
"Description"=
"Path"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\wacom.com/WacomTabletPlugin]
"Description"=
"Path"=C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll


C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt

C:\Users\Kryštof\AppData\Roaming\Mozilla\Firefox\Profiles\supv2zeo.default\extensions\
2020Player_IKEA@2020Technologies.com
maps@ovi.com
support@lastpass.com
{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
{a7c6cf7f-112c-4500-a7ea-39801a327e5f}

C:\Users\Kryštof\AppData\Roaming\Mozilla\Firefox\Profiles\supv2zeo.default\searchplugins\
s-amazon.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-09-29 219304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-11-11 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2015-10-29 886488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}]
Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\64bit\VIPAddOnForIE64.dll [2011-06-30 2417264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-10-29 2339032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-11-11 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-09-29 153768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-11-11 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2015-10-29 712304]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C63CD127-A1CB-4D49-A4F7-D6F88A917BE6}]
Symantec VIP Access Add-On - C:\Program Files (x86)\Symantec\VIP Access Client\VIPAddOnForIE.dll [2011-06-30 2089584]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-10-29 1733240]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-11-11 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IntelPAN"=C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [2011-07-28 1935120]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2011-04-26 310912]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-08-11 167704]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-08-11 392472]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-08-11 416024]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DisplayFusion"=C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [2014-12-16 6780256]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2012-08-28 3671904]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-03-13 7451928]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2013-04-23 1561968]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"=rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor []
"IJNetworkScanUtility"=C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE [2010-01-18 124256]
"RotateImage"=C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-30 55808]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2013-04-23 311152]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Secunia PSI Tray.lnk - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-08-09 390144]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\qengine]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Labeljoy 5\LotoUpdate.exe"="C:\Program Files (x86)\Labeljoy 5\LotoUpdate.exe:*:Enabled:LotoUpdate"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave5"=wdmaud.drv
"mixer5"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install - 
.scr - config - 
.txt - open - C:\Windows\NOTEPAD.EXE %1

======List of files/folders created in the last 1 month======

2015-11-12 14:59:13 ----D---- C:\Program Files\trend micro
2015-11-12 14:59:12 ----D---- C:\rsit
2015-11-12 12:05:02 ----SHD---- C:\$RECYCLE.BIN
2015-11-12 12:04:54 ----A---- C:\ComboFix.txt
2015-11-12 11:20:54 ----A---- C:\Windows\zip.exe
2015-11-12 11:20:54 ----A---- C:\Windows\SWSC.exe
2015-11-12 11:20:54 ----A---- C:\Windows\SWREG.exe
2015-11-12 11:20:54 ----A---- C:\Windows\sed.exe
2015-11-12 11:20:54 ----A---- C:\Windows\PEV.exe
2015-11-12 11:20:54 ----A---- C:\Windows\NIRCMD.exe
2015-11-12 11:20:54 ----A---- C:\Windows\MBR.exe
2015-11-12 11:20:54 ----A---- C:\Windows\grep.exe
2015-11-12 11:20:08 ----D---- C:\Qoobox
2015-11-12 11:19:37 ----D---- C:\Windows\erdnt
2015-11-12 10:39:47 ----A---- C:\Windows\system32\drivers\avchv.sys
2015-11-12 10:37:55 ----D---- C:\Windows\LastGood
2015-11-12 10:37:51 ----A---- C:\Windows\system32\drivers\avckf.sys
2015-11-12 10:37:51 ----A---- C:\Windows\system32\drivers\avc3.sys
2015-11-12 10:36:01 ----D---- C:\Program Files\Bitdefender
2015-11-12 10:36:00 ----A---- C:\Windows\system32\drivers\trufos.sys
2015-11-12 10:36:00 ----A---- C:\Windows\system32\drivers\gzflt.sys
2015-11-11 03:57:55 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2015-11-11 03:57:55 ----A---- C:\Windows\SYSWOW64\wups.dll
2015-11-11 03:57:55 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2015-11-11 03:57:55 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2015-11-11 03:57:55 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wuwebv.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wups2.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wups.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wudriver.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wucltux.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wuaueng.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wuauclt.exe
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wuapp.exe
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wuapi.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2015-11-11 03:57:55 ----A---- C:\Windows\system32\WinSetupUI.dll
2015-11-11 03:57:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-11-11 03:57:49 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-11-11 03:57:49 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-11-11 03:57:49 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\occache.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-11-11 03:57:48 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-11-11 03:57:48 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-11-11 03:57:48 ----A---- C:\Windows\system32\iernonce.dll
2015-11-11 03:57:48 ----A---- C:\Windows\system32\ie4uinit.exe
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\jscript.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-11-11 03:57:46 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-11-11 03:57:46 ----A---- C:\Windows\system32\urlmon.dll
2015-11-11 03:57:46 ----A---- C:\Windows\system32\occache.dll
2015-11-11 03:57:46 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-11-11 03:57:46 ----A---- C:\Windows\system32\iedkcs32.dll
2015-11-11 03:57:45 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-11-11 03:57:45 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-11-11 03:57:45 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-11-11 03:57:45 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-11-11 03:57:45 ----A---- C:\Windows\system32\msfeeds.dll
2015-11-11 03:57:45 ----A---- C:\Windows\system32\iesetup.dll
2015-11-11 03:57:45 ----A---- C:\Windows\system32\ieapfltr.dll
2015-11-11 03:57:45 ----A---- C:\Windows\system32\dxtrans.dll
2015-11-11 03:57:44 ----A---- C:\Windows\system32\iertutil.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-11-11 03:57:43 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-11-11 03:57:43 ----A---- C:\Windows\system32\vbscript.dll
2015-11-11 03:57:43 ----A---- C:\Windows\system32\jsproxy.dll
2015-11-11 03:57:43 ----A---- C:\Windows\system32\dxtmsft.dll
2015-11-11 03:57:42 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-11-11 03:57:42 ----A---- C:\Windows\system32\mshtmled.dll
2015-11-11 03:57:42 ----A---- C:\Windows\system32\ieui.dll
2015-11-11 03:57:42 ----A---- C:\Windows\system32\ieframe.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\wininet.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\webcheck.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\jscript9diag.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\jscript9.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\jscript.dll
2015-11-11 03:57:41 ----A---- C:\Windows\system32\ieUnatt.exe
2015-11-11 03:57:40 ----A---- C:\Windows\system32\msrating.dll
2015-11-11 03:57:40 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-11-11 03:57:39 ----A---- C:\Windows\system32\mshtml.dll
2015-11-11 03:56:39 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-11-11 03:56:39 ----A---- C:\Windows\system32\kerberos.dll
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-11-11 03:56:38 ----A---- C:\Windows\SYSWOW64\bcryptprimitives.dll
2015-11-11 03:56:38 ----A---- C:\Windows\system32\schannel.dll
2015-11-11 03:56:38 ----A---- C:\Windows\system32\ncrypt.dll
2015-11-11 03:56:38 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-11-11 03:56:38 ----A---- C:\Windows\system32\drivers\cng.sys
2015-11-11 03:56:38 ----A---- C:\Windows\system32\bcryptprimitives.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-11-11 03:56:37 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\wow32.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\setup16.exe
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-11-11 03:56:37 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-11-11 03:56:37 ----A---- C:\Windows\system32\wow64win.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\wow64cpu.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\wow64.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\winsrv.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\wdigest.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\TSpkg.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\sspisrv.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\sspicli.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\srcore.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\srclient.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\smss.exe
2015-11-11 03:56:37 ----A---- C:\Windows\system32\secur32.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\rstrui.exe
2015-11-11 03:56:37 ----A---- C:\Windows\system32\rpcrt4.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\ntvdm64.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\ntdll.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\msv1_0.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\lsass.exe
2015-11-11 03:56:37 ----A---- C:\Windows\system32\lsasrv.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\KernelBase.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\kernel32.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2015-11-11 03:56:37 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2015-11-11 03:56:37 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2015-11-11 03:56:37 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-11-11 03:56:37 ----A---- C:\Windows\system32\csrsrv.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\cryptbase.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\credssp.dll
2015-11-11 03:56:37 ----A---- C:\Windows\system32\conhost.exe
2015-11-11 03:56:37 ----A---- C:\Windows\system32\auditpol.exe
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-11-11 03:56:36 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\user.exe
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\instnm.exe
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2015-11-11 03:56:36 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-11-11 03:56:36 ----A---- C:\Windows\system32\msobjs.dll
2015-11-11 03:56:36 ----A---- C:\Windows\system32\msaudite.dll
2015-11-11 03:56:36 ----A---- C:\Windows\system32\apisetschema.dll
2015-11-11 03:56:36 ----A---- C:\Windows\system32\adtschema.dll
2015-11-11 03:56:26 ----A---- C:\Windows\system32\drivers\tdx.sys
2015-11-11 03:56:26 ----A---- C:\Windows\system32\drivers\afd.sys
2015-11-11 03:56:25 ----A---- C:\Windows\SYSWOW64\shimeng.dll
2015-11-11 03:56:25 ----A---- C:\Windows\SYSWOW64\sdbinst.exe
2015-11-11 03:56:25 ----A---- C:\Windows\SYSWOW64\apphelp.dll
2015-11-11 03:56:25 ----A---- C:\Windows\system32\shimeng.dll
2015-11-11 03:56:25 ----A---- C:\Windows\system32\sdbinst.exe
2015-11-11 03:56:25 ----A---- C:\Windows\system32\apphelp.dll
2015-11-11 03:56:25 ----A---- C:\Windows\system32\aelupsvc.dll
2015-11-11 03:56:24 ----A---- C:\Windows\system32\win32k.sys
2015-11-11 03:56:14 ----A---- C:\Windows\system32\drivers\ndis.sys
2015-11-11 03:56:13 ----A---- C:\Windows\SYSWOW64\InkEd.dll
2015-11-11 03:56:13 ----A---- C:\Windows\system32\jnwmon.dll
2015-11-11 03:56:13 ----A---- C:\Windows\system32\InkEd.dll
2015-11-09 13:28:01 ----D---- C:\Program Files (x86)\NetviewX
2015-11-09 11:24:24 ----D---- C:\Program Files (x86)\Mozilla Firefox
2015-11-05 17:48:10 ----A---- C:\Windows\Viewer.INI
2015-11-05 09:44:40 ----D---- C:\Program Files (x86)\Media Freeware
2015-10-29 11:27:01 ----D---- C:\Windows\SYSWOW64\data
2015-10-29 11:26:52 ----D---- C:\Program Files (x86)\AVC_OCX
2015-10-29 11:26:39 ----N---- C:\Windows\SYSWOW64\swscale-3.1.801.dll
2015-10-29 11:26:38 ----N---- C:\Windows\SYSWOW64\avutil-54.20.800.dll
2015-10-29 11:26:38 ----N---- C:\Windows\SYSWOW64\avformat-56.25.801.dll
2015-10-29 11:26:38 ----N---- C:\Windows\SYSWOW64\avcodec-56.26.800.dll
2015-10-29 11:26:33 ----D---- C:\Program Files (x86)\AVTECH
2015-10-29 10:05:45 ----D---- C:\Program Files (x86)\IPCOCX_PX
2015-10-15 02:27:09 ----A---- C:\Windows\system32\invagent.dll
2015-10-15 02:27:09 ----A---- C:\Windows\system32\generaltel.dll
2015-10-15 02:27:09 ----A---- C:\Windows\system32\devinv.dll
2015-10-15 02:27:09 ----A---- C:\Windows\system32\CompatTelRunner.exe
2015-10-15 02:27:09 ----A---- C:\Windows\system32\appraiser.dll
2015-10-15 02:27:09 ----A---- C:\Windows\system32\aeinv.dll
2015-10-15 02:27:09 ----A---- C:\Windows\system32\acmigration.dll
2015-10-14 08:08:00 ----A---- C:\Windows\system32\shell32.dll
2015-10-14 08:07:59 ----A---- C:\Windows\SYSWOW64\shell32.dll
2015-10-14 08:07:59 ----A---- C:\Windows\system32\ExplorerFrame.dll
2015-10-14 08:07:58 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2015-10-14 08:05:18 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2015-10-14 08:05:18 ----A---- C:\Windows\system32\setbcdlocale.dll
2015-10-14 08:05:18 ----A---- C:\Windows\system32\drivers\appid.sys
2015-10-14 08:05:18 ----A---- C:\Windows\system32\appidsvc.dll
2015-10-14 08:05:18 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 08:05:18 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 08:05:18 ----A---- C:\Windows\system32\appidapi.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\ucrtbase.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l2-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-2-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\ucrtbase.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 08:04:19 ----A---- C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-13 01:29:08 ----A---- C:\Windows\SYSWOW64\msvcr120_clr0400.dll
2015-10-13 01:22:02 ----A---- C:\Windows\system32\msvcr120_clr0400.dll

======List of files/folders modified in the last 1 month======

2015-11-12 14:59:17 ----D---- C:\Windows\Prefetch
2015-11-12 14:59:13 ----D---- C:\Program Files
2015-11-12 14:40:20 ----D---- C:\Windows\Temp
2015-11-12 14:37:57 ----D---- C:\Windows\System32
2015-11-12 12:01:07 ----D---- C:\Windows
2015-11-12 12:01:07 ----A---- C:\Windows\system.ini
2015-11-12 12:00:54 ----D---- C:\Windows\system32\drivers\etc
2015-11-12 11:59:49 ----D---- C:\ProgramData
2015-11-12 11:30:14 ----AD---- C:\ProgramData\TEMP
2015-11-12 11:29:57 ----D---- C:\Windows\SYSWOW64\drivers
2015-11-12 11:29:57 ----D---- C:\Windows\SysWOW64
2015-11-12 11:29:57 ----D---- C:\Windows\AppPatch
2015-11-12 11:29:56 ----D---- C:\Program Files (x86)\Common Files
2015-11-12 11:20:11 ----D---- C:\Windows\system32\drivers
2015-11-12 10:36:14 ----D---- C:\Users\Kryštof\AppData\Roaming\QuickScan
2015-11-12 04:19:40 ----D---- C:\Windows\rescache
2015-11-12 03:51:24 ----D---- C:\Windows\inf
2015-11-12 03:51:24 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-11-12 03:46:34 ----A---- C:\Windows\SYSWOW64\log.txt
2015-11-12 03:44:37 ----D---- C:\Windows\winsxs
2015-11-12 03:42:39 ----D---- C:\Windows\system32\config
2015-11-12 03:42:00 ----D---- C:\Config.Msi
2015-11-12 03:41:59 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2015-11-12 03:39:06 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-11-12 03:39:06 ----D---- C:\Windows\system32\cs-CZ
2015-11-12 03:38:58 ----D---- C:\Windows\SYSWOW64\en-US
2015-11-12 03:38:58 ----D---- C:\Program Files\Internet Explorer
2015-11-12 03:38:57 ----D---- C:\Windows\system32\en-US
2015-11-12 03:38:57 ----D---- C:\Program Files (x86)\Internet Explorer
2015-11-12 03:38:51 ----D---- C:\Windows\system32\migration
2015-11-12 03:38:37 ----D---- C:\Users\Kryštof\AppData\Roaming\qBittorrent
2015-11-12 03:23:26 ----D---- C:\Windows\system32\MRT
2015-11-12 03:21:20 ----D---- C:\Windows\Microsoft.NET
2015-11-12 03:18:57 ----RSD---- C:\Windows\assembly
2015-11-12 03:12:01 ----A---- C:\Windows\system32\MRT.exe
2015-11-12 03:10:13 ----SHD---- C:\Windows\Installer
2015-11-12 03:03:17 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2015-11-12 03:01:23 ----D---- C:\Program Files\Windows Journal
2015-11-12 03:00:32 ----SHD---- C:\System Volume Information
2015-11-11 03:56:03 ----D---- C:\Windows\system32\catroot2
2015-11-10 08:53:10 ----RD---- C:\Program Files (x86)
2015-11-09 16:50:53 ----D---- C:\Users\Kryštof\AppData\Roaming\iSpy
2015-11-09 13:46:11 ----D---- C:\Windows\Netview_X OCX
2015-11-05 16:28:37 ----D---- C:\Users\Kryštof\AppData\Roaming\vlc
2015-11-05 15:50:37 ----D---- C:\Users\Kryštof\AppData\Roaming\dvdcss
2015-11-05 09:59:04 ----D---- C:\Program Files (x86)\EasyPHP-DevServer-14.1VC11
2015-11-05 09:34:34 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-10-29 12:54:18 ----D---- C:\Capture
2015-10-29 11:26:41 ----A---- C:\psapi.dll
2015-10-29 10:01:33 ----D---- C:\Program Files\iSpy
2015-10-29 08:53:49 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2015-10-29 08:52:42 ----D---- C:\Program Files\Microsoft Office 15
2015-10-27 17:02:36 ----D---- C:\Users\Kryštof\AppData\Roaming\Arduino15
2015-10-21 02:04:22 ----D---- C:\Windows\system32\inetsrv
2015-10-21 02:01:57 ----SD---- C:\ProgramData\Microsoft
2015-10-20 11:00:45 ----D---- C:\Windows\Searcher
2015-10-20 11:00:45 ----D---- C:\Program Files (x86)\Searcher
2015-10-15 16:32:30 ----SD---- C:\Windows\system32\CompatTel
2015-10-15 16:32:29 ----D---- C:\Windows\system32\appraiser
2015-10-15 02:27:25 ----D---- C:\Windows\system32\CodeIntegrity
2015-10-15 02:27:25 ----D---- C:\Windows\system32\Boot

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avc3;avc3; C:\Windows\system32\DRIVERS\avc3.sys [2013-04-17 718840]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-04-26 557848]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 speedfan;speedfan; C:\Windows\SysWOW64\speedfan.sys [2011-03-18 29592]
R0 trufos;trufos; C:\Windows\system32\DRIVERS\trufos.sys [2013-05-28 382536]
R1 bdfwfpf;bdfwfpf; \??\C:\Program Files\Bitdefender\Antivirus Free Edition\bdfwfpf.sys [2013-07-02 121928]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2012-10-02 283200]
R1 lenovo.smi;Lenovo System Interface Driver; C:\Windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
R1 MIPFSv364;MIPFSv364; \??\C:\Windows\system32\drivers\MIPFSv364.sys [2010-09-20 190504]
R1 MIPv464;MIPv464; \??\C:\Windows\system32\drivers\MIPv464.sys [2010-11-02 66680]
R1 PHCORE;PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [2011-07-09 32104]
R1 TPPWRIF;TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [2011-08-31 14960]
R1 truecrypt;truecrypt; C:\Windows\System32\drivers\truecrypt.sys [2013-01-22 231376]
R3 5U877;USB Video Device; C:\Windows\system32\DRIVERS\5U877.sys [2011-03-05 166016]
R3 avckf;avckf; C:\Windows\system32\DRIVERS\avckf.sys [2013-04-17 593144]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2011-03-24 1576064]
R3 gzflt;gzflt; C:\Windows\system32\DRIVERS\gzflt.sys [2013-04-22 148696]
R3 IBMPMDRV;IBMPMDRV; C:\Windows\system32\DRIVERS\ibmpmdrv.sys [2011-08-11 39024]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2011-08-09 12289472]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
R3 iwdbus;IWD Bus Enumerator; C:\Windows\system32\DRIVERS\iwdbus.sys [2011-06-22 25496]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2011-03-23 77936]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETwNs64.sys [2011-08-04 8604672]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\Windows\system32\DRIVERS\psadd.sys [2011-12-22 40248]
R3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf_amd64.sys [2013-10-14 18456]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2013-12-21 34032]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2011-05-19 1442352]
R3 TVTI2C;Lenovo SM bus driver; C:\Windows\system32\DRIVERS\Tvti2c.sys [2009-09-24 41536]
R3 VBAudioVACMME;System Audio Driver (WDM); C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [2013-08-17 38272]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2014-10-13 38080]
S3 AVerAF35;AVerMedia A867 USB DVB-T; C:\Windows\System32\Drivers\AVerAF35.sys [2012-11-29 804736]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-12-21 80384]
S3 BTWAMPFL;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2011-03-16 436776]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2011-03-03 150568]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2011-02-25 163880]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2011-02-22 39976]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2011-02-25 21544]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-10-13 110336]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2013-12-21 14448]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2013-12-21 27760]
S3 hidkmdf;KMDF Driver; C:\Windows\system32\DRIVERS\hidkmdf.sys [2014-08-06 14136]
S3 intaud_WaveExtensible;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2011-06-22 34200]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\Windows\system32\DRIVERS\netaapl64.sys [2013-07-25 23040]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\Windows\syswow64\NSNDIS5.SYS []
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 Rockusb;Driver for Rockusb Device; C:\Windows\system32\DRIVERS\rockusb.sys [2012-11-06 64752]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver; C:\Windows\system32\DRIVERS\RtsPStor.sys [2010-12-08 329832]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2010-11-21 109056]
S3 SMIUSBAVCALL;SMI Grabber Device 4CH1CH ALL; C:\Windows\System32\Drivers\SmiUsbGrabber3F.sys [2011-09-27 153344]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2014-10-13 169288]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2014-10-13 21320]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2014-10-13 188232]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2014-10-13 158024]
S3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-10-13 206080]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 USBAAPL64;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB RS-232 Emulation Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.12.0;ABBYY FineReader 12 PE Licensing Service; C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe [2014-07-13 961744]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-05-08 65432]
R2 Apache;Apache; C:\PROGRA~2\EASYPH~1.1VC\binaries\apache\bin\eds-httpd.exe [2013-11-22 22016]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [2011-03-25 968480]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-10-07 2780856]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2010-12-16 198784]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DisplayFusionService;DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [2014-12-16 3075440]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2011-07-28 1517328]
R2 gzserv;Bitdefender Antivirus Free Edition; C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe [2013-10-23 69368]
R2 IBMPMSVC;ThinkPad PM Service; C:\Windows\system32\ibmpmsvc.exe [2011-08-11 45928]
R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service; C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2011-02-22 326168]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 NovaPdfServer;novaPDF Server; C:\Program Files\Softland\novaPDF 8\Server\novapdfs.exe [2015-06-09 41760]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2011-07-28 844560]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 Secunia PSI Agent;Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [2013-10-14 1228504]
R2 Secunia Update Agent;Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [2013-10-14 660184]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-10-13 743688]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
R2 VIPAppService;VIPAppService; C:\Program Files (x86)\Symantec\VIP Access Client\VIPAppService.exe [2011-06-30 82544]
R3 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-08-31 87400]
S2 Autodesk Content Service;Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [2012-01-31 19232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-11 103608]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-04-11 124088]
S2 gupdate;Google Update Service (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S2 HyperW7Svc;HyperW7 Service; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2011-07-09 144232]
S2 MySQL;MySQL; C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files (x86)\MySQL\MySQL Server 5.0\my.ini MySQL []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-23 269000]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2012-08-13 1432400]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-01 144200]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-10-31 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2015-11-09 147624]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-07-28 340240]
S3 ose;Office  Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-12-04 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2013-12-04 5132888]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 PwmEWSvc;Cisco EnergyWise Enabler; C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.EXE [2011-08-31 173416]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-04-11 50864]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2014-04-11 139944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Samovolná platba přes Paypal

#2 Příspěvek od Rudy »

Zdravím!
Fórum viry.cz je určeno home userům. Pro firemní PC použijte službu: http://neslape.cz/?utm_campaign=neslape ... ium=banner .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

karelsvoboda
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 12 lis 2015 14:55

Re: Samovolná platba přes Paypal

#3 Příspěvek od karelsvoboda »

Toho jsem se bál, že sklouznu do škatulky firemní. :)
Je to problém soukromého charakteru, byť na pracovním pc, a osobně bych se ani jako firma neoznačoval, ale chápu vaše pohnutky.

Tak hezký den přeji.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Samovolná platba přes Paypal

#4 Příspěvek od Rudy »

Bohužel ano, v tomto jsou pravidla neúprosná. Na odkazu, který jsem vám dal, získáte rovněž kvalitní podporu. Hezký den i vám! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno